Company Data When a Rental Unit Is Returned: What Is Required

Summary
Securing company data before a rented laptop goes back: data inventory, migration, wiping, and the written evidence worth keeping.
The end of a rental term is usually treated as a logistics matter: units are gathered, counted, then collected. The part most often skipped is the riskiest one — what remains inside the device as it leaves your office.
This article sets out a procedure IT and admin teams can adopt as a standing checklist, so returning units leaves behind no data that should never have left the organisation.
Why This Is Not a Formality
A device used for months holds far more than its user realises. Beyond work documents in obvious folders sits a layer rarely considered: credentials saved in browsers, corporate network connection history, temporary files from email attachments once opened, local copies of cloud folders, and application profiles storing access tokens.
For organisations subject to data protection obligations, an oversight here is not merely technical. The duty to safeguard personal data remains with the company as data controller, regardless of who owns the hardware.
Step One: Inventory Before Scheduling Collection
Start from a list of units and who used them. For fleets that changed hands during the contract, this record is often inaccurate, and an unrecorded unit is a unit nobody will check.
For each unit, determine its category: was it ever used to process personal data, financial data, or data covered by a client confidentiality agreement. That category determines how strict the wiping treatment must be.
Give users a deadline to move their own personal files. Without a clear deadline, this stage is invariably what delays collection day.
Step Two: Migrate What Is Still Needed
Confirm that still-relevant work files already sit in company storage rather than only on the device. This sounds obvious, but in practice there are often documents that were never synchronised because they lived outside monitored folders.
Check the non-document items too: templates users created, customised application configurations, and project files that live inside application folders. Losing these is rarely fatal, but it is disruptive when the user moves to a new unit.
Step Three: Revoke Access, Do Not Merely Delete Files
Deleting files does not revoke access. This distinction is frequently missed.
Remove the device from the corporate device management system and from the trusted device lists on email accounts and collaboration platforms. Revoke corporate network certificates and profiles, including office wireless configurations and remote access clients.
Sign all accounts out of browsers and applications, then clear stored credentials. For organisations using a password manager, ensure that device's session is revoked server-side rather than merely closed locally.
Step Four: Wiping Matched to Category
For devices whose storage has been encrypted from the outset, destroying the encryption key and returning the device to factory settings provides protection adequate for most business needs, because remaining data cannot be read without that key.
For devices holding sensitive-category data, or where a client agreement demands a particular standard, discuss the required procedure with your rental provider at the start of the contract. This is precisely why encryption should be enabled when a unit is first handed over rather than considered at the end.
What must be avoided is treating "delete files and empty the recycle bin" as wiping. That merely marks space as available.
Step Five: Keep the Evidence
This is the part most often missing, and the part most needed when an audit or a question arises later.
Record for each unit: serial number, wiping date, method used, who performed it, and who witnessed it. Include confirmation that the device was removed from management systems and trusted device lists.
Store this alongside the unit handover record. Handover procedure generally is covered in our rental unit handover article.
Mistakes That Recur
Delegating the whole process to users. Users know their documents, but not the network profiles, certificates or tokens stored within applications.
Checking only units used by senior staff. Sensitive data frequently sits on operational staff units that process documents every day.
Scheduling collection before wiping is complete. Time pressure on collection day is the most common reason security steps get skipped.
Forgetting damaged units. A device that will not power on still holds data on its storage, and these are precisely the units most likely to leave without procedure.
Categorising Data Before Deciding Treatment
Not every unit demands the same treatment, and treating them identically wastes time on low-risk units while being insufficiently thorough on high-risk ones.
The first category is units used only to access central systems without storing local files. Reception units, data entry terminals and kiosk stations usually sit here. Treatment is lightest because data never persists.
The second is general work units holding operational documents. This is the largest share of the fleet, and standard treatment suffices.
The third is units processing personal data, financial data, or data covered by client confidentiality agreements. HR, finance, legal, and teams handling specific client projects sit here. Treatment is strictest and the evidence most important to retain.
Determine each unit's category when it is issued rather than when it is returned. Deciding at the end means relying on memory of what was done on that device across many months.
Encryption as an Opening Decision, Not a Closing One
This part determines how complicated the return process becomes, and the decision is made on day one.
If storage is encrypted from the moment a unit is first prepared, destroying the encryption key renders all remaining data unreadable. This provides protection adequate for most business needs, and the process is quick.
If encryption is only considered approaching return, options become far more limited. Data already written unencrypted does not become protected merely because encryption is enabled afterwards.
So enable encryption as part of the standard system image rather than as a separate step that can be missed. Configuration standardisation is covered in our uniform system image article.
For organisations under data protection obligations, this decision also affects your position when a unit is lost mid-contract, not only at return.
Building an Evidence Sheet That Survives an Audit
Records made carelessly will not help when a question arrives six months later. Several things make a record genuinely useful.
One line per unit rather than one note per batch. When questions arise, they always concern a specific unit.
Include the serial number, not merely brand and model. The serial number is the only identifier binding a record to physical hardware.
Include the names of the person performing and the person witnessing. Records without names are hard to stand behind.
Include confirmation of access revocation, not only data wiping. These are separate steps, and the first is frequently assumed covered by the second when it is not.
Store it alongside the provider's collection record so the two can be reconciled. The record format sits in our rental handover article.
Handling Units That Will Not Power On
This is the case most likely to leave without procedure, precisely because it cannot be processed the usual way.
A completely failed unit still holds data on its storage. Not powering on does not mean unreadable to anyone with the tools and intent.
The first step remains identical: revoke all access for that device from management systems, networks and trusted device lists. This can be done without touching the hardware.
Then state the condition in writing to the provider and agree how it will be handled. Some providers offer a specific procedure for units that cannot be processed normally.
Record that agreement alongside your other unit records. A unit leaving without any record is the hardest gap to explain when questions come later.
Frequently Asked Questions
Is a factory reset sufficient?
For devices encrypted from the outset, it is generally adequate for ordinary business needs. For sensitive-category data or specific contractual obligations, agree a stricter procedure with the provider in advance.
Who is responsible, us or the provider?
Data protection duties rest with the company as data controller. A provider can assist with the process, but the division of responsibility should be written into the contract rather than assumed.
What about a unit lost mid-contract?
Treat it as an incident rather than simply a lost asset. Revoke all access for that device immediately, then record the event. If encryption was active, the risk is far more contained.
Making It Standard Procedure
Turn this checklist into a single sheet completed per unit, then make it a precondition before collection is scheduled. Organisations that treat unit return as a controlled process rather than a last-day logistics errand almost never encounter problems here.
References & Sources
Data sanitisation methods, including cryptographic key deletion, follow NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization (accessed 24 September 2026). In Indonesia, the duty to protect personal data is set out in Law No. 27 of 2022 on Personal Data Protection (accessed 24 September 2026).